CVE-2018-6970 is an out-of-bounds read vulnerability in the Message Framework library affecting VMware Horizon 6 (prior to 6.2.7), Horizon 7 (prior to 7.5.1), and Horizon Client (prior to 4.8.1) on Windows systems. This medium-severity vulnerability (CVSS 6.5) allows a less-privileged user to potentially leak sensitive information from a privileged process without user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.8.1CPE matchmatch criteria | cpe:2.3:a:vmware:horizon_client:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.7CPE matchmatch criteria | cpe:2.3:a:vmware:horizon_view:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:horizon_view:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.